Executive brief
The GNU tar utility, a common tool for managing file archives, contains a vulnerability when used in conjunction with FTP sessions. An attacker could exploit this flaw to execute unauthorized commands on the system. This could lead to a complete system compromise, unauthorized data access, or service disruption.
Technical details
A command injection or remote code execution vulnerability exists in GNU tar when it is invoked during FTP sessions. The flaw likely stems from improper handling of filenames or archive metadata that are passed to the shell or system execution environment during automated FTP processing. A remote, unauthenticated attacker can exploit this by providing specially crafted inputs that trigger command execution. This allows for full system access with the privileges of the user running the tar process. While the specific root cause is categorized as 'Other' in historical records, the impact is a standard remote command execution (RCE) pattern.
Affected products
- GNU tar
Timeline
- 1997-01-01: disclosed: Vulnerability published in NVD.